CVE-2017-7485: PostgreSQL

Medium severity, CVSS 5.9. EPSS: 2% chance of exploitation in the next 30 days.

In PostgreSQL 9.3.x before 9.3.17, 9.4.x before 9.4.12, 9.5.x before 9.5.7, and 9.6.x before 9.6.3, it was found that the PGREQUIRESSL environment variable was no longer enforcing a SSL/TLS connection to a PostgreSQL server. An active Man-in-the-Middle attacker could use this flaw to strip the SSL/TLS protection from a connection between a client and a server.

Affected products

  • PostgreSQL PostgreSQL: version 9.3 only; version 9.3.1 only; version 9.3.2 only; version 9.3.3 only; version 9.3.4 only; version 9.3.5 only; …

Published 2017-05-12. Last modified 2026-06-17.